Files
lumbridge-code/AGENTS.md
T
Metal AgentandClaude Opus 5 219c674aea Read Claude Code's own quota endpoint, not just its status line
Decision 0015 rejected the account usage endpoint because AGENTS.md forbade
reading a harness's credential. The rule was written to stop one program
helping itself to another's secrets, and it was catching a legitimate use with
it: the user asking about their own subscription, through software they
installed to do that. AGENTS.md now states the narrow allowance instead of an
absolute the project does not hold, and 0016 records it.

The status line stays. It is free and it speaks every turn. What it cannot do
is report the per-model weekly limits a Max plan meters separately, or answer
at all before a session has taken a turn. The first live reading found the
account-wide seven-day window at 38% left and a per-model weekly window at 77%
left — a second ceiling the footer previously could not see.

Constraints the credential is read under, all enforced in code: access token
only, never the refresh token; zeroed on drop, along with the file buffer it
was borrowed out of; unprintable by construction, since HarnessError carries no
owned strings and AccessToken's Debug is hand-written; identified as
lumbridge/<version>, because sending claude-code/2.1.0 would make our traffic
indistinguishable from the harness's in Anthropic's logs; and off entirely
under LUMBRIDGE_CLAUDE_OAUTH=0.

The request runs on a detached thread with a slow refresh and a 429 backoff, so
a ten-second round trip cannot stall the transcript follower or make quitting
wait on the network, and one surface failing does not fault the other two.

Footer polish on top: the harness name prints once per group instead of in
front of each of its four windows, each quota carries a short scope pill
(5h, 7d, Fable wk, tokens) where an invisible BORDER-weight label used to be,
quotas sort ahead of spend, and a window under ten percent turns its headline
amber — value colour on the number, provenance colour on the meter, never
mixed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-31 22:04:34 -07:00

2.6 KiB

AGENTS.md

These rules apply to the entire Lumbridge repository.

Product boundary

Lumbridge is a terminal/workspace runtime and ACP client. It may host, supervise, and observe coding harnesses, but must not silently impersonate them, harvest their private credentials, or claim provider quota data that cannot be verified.

Credential use is narrow and named. A harness's stored credential may be read only to ask that same provider a documented question about the user's own account, and only where the answer cannot be obtained another way. Under that allowance a credential must never be persisted, logged, copied into application state, written to a crash report, or passed as a command-line argument; it must be released as soon as the request it authorises has been made; and any request it authorises must identify Lumbridge as the caller. A refresh token is never used — renewing a credential is the harness's job, not Lumbridge's. Every such use is named in a decision record, and each is switchable off by the user. Reading a credential for anything other than a use recorded that way is out of bounds. See decision 0016.

Research boundary

Upstream repositories are cloned outside this Git repository under the desktop workspace's Research/ directory. They are references, not vendored code.

  • Do not copy upstream implementation code without an explicit license review.
  • Record the source repository and relevant license for any adapted design.
  • AGPL/GPL and unlicensed repositories may be studied for behavior and UX only unless the project deliberately changes its licensing strategy.

Engineering rules

  • Keep provider, harness, protocol, terminal, persistence, and UI boundaries separate. A provider is not a harness and ACP is not a provider API.
  • Preserve a PTY fallback. ACP adds structure but must not be required to open a normal shell or run an arbitrary CLI.
  • Keep secrets out of SQLite, logs, crash reports, command-line arguments, and repository files. Store only opaque secret references in application state.
  • Usage values must include a provenance and confidence classification.
  • Avoid platform behavior hidden behind scattered cfg blocks; isolate it in platform adapters with shared contract tests.
  • No telemetry is enabled by default. Any future telemetry must be documented, opt-in, redacted, and independently disableable.

Verification

Before committing Rust changes, run:

./scripts/ci.sh

Keep bacon running during development. Tests must use synthetic fixtures; real agent transcripts, subscription state, private source, and credentials are never test data.